A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulnerability is the function pdf2swf of the file /pdf2swf. The manipulation of the argument file leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/Rain1er/report/blob/main/nxb/rce1.md | Broken Link |
| https://vuldb.com/?ctiid.296731 | Permissions Required VDB Entry |
| https://vuldb.com/?id.296731 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.500507 | Third Party Advisory VDB Entry |
| https://github.com/Rain1er/report/blob/main/nxb/rce1.md | Broken Link |
Configurations
History
29 Jan 2026, 02:09
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Hzmanyun education And Training System
Hzmanyun |
|
| References | () https://github.com/Rain1er/report/blob/main/nxb/rce1.md - Broken Link | |
| References | () https://vuldb.com/?ctiid.296731 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.296731 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.500507 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:hzmanyun:education_and_training_system:3.1.1:*:*:*:*:*:*:* | |
| Summary |
|
25 Feb 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Rain1er/report/blob/main/nxb/rce1.md - |
25 Feb 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-25 11:15
Updated : 2026-01-29 02:09
NVD link : CVE-2025-1676
Mitre link : CVE-2025-1676
CVE.ORG link : CVE-2025-1676
JSON object : View
Products Affected
hzmanyun
- education_and_training_system
